Implementation of SOC using ELK with Integration of Wazuh and Dedicated File Integrity Monitoring

Ns Akshai Sankar, K. A. Fasila · 2023

The Security Operations Center (SOC) is currently a crucial component of the protection strategy and data security system that reduces the degree of vulnerability of information systems to both internal and external hazards. The SOC will gather events from various security components, evaluate them, spot anomalies, and establish alerting protocols. The implementation of a SOC architecture will center on agents running on monitored hosts and forwarding log data to a central server that serves as a hub.ELK and Wazuh are the different tools that we shall employ. Elasticsearch, Logstash, and Kibana are the three open-source technologies that make up the ELK Stack. Wazuh integration with ELK to gather and aggregate security data for spotting threats, intrusions, and behavioral anomalies. Several rules that will set off alarms when odd or suspicious activity takes place will be configured.With this architectural paradigm, we can create and keep a situational image of the organization’s security while responding quickly to any changes that may occur. Our goal is to build a SOC environment that enables dynamic security and serves as a true fortress of analysis, monitoring, prevention, and restoration.FIM usually falls under data loss prevention policy of organisations but it is inbuilt in this tool.

Read the paper · More papers on PaperTik